CNNVD-202511-379 Information

CNNVD ID

CNNVD-202511-379

CVE-2025-31954

  • CNNVD Published: 2025-11-05

Description (Chinese)

HCL iAutomate是印度HCL公司的一款功能强大的智能运行手册自动化产品。 HCL iAutomate v6.5.1版本和v6.5.2版本存在安全漏洞,该漏洞源于使用HTTP GET方法处理请求并在查询字符串中包含敏感信息,可能导致信息泄露。

Description (English)

HCL iAutomate is an automated product of a powerful smart running manual for HCL in India. HCL iAutomate v6.5.1 and v6.5.2 have a security loophole, which arises from the use of HTTP GET to process requests and to include sensitive information in search strings, which may lead to the disclosure of information.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

HCL

Published

2025-11-05

Last Modified

2026-02-24

References

https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0125011

Patch

https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0125011

Share on: